Техническая информация
- '%TEMP%\ose2184.tmp'
- '%TEMP%\ose2184.tmp' run
- %TEMP%\wd4sx.wmf
- %TEMP%\ose2184.tmp
- %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\62axopq5\icanhazip_com[1].txt
- %WINDIR%\temp\~07f8deea\133750506.txt
- %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\62axopq5\icanhazip_com[1].txt
- %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\62axopq5\icanhazip_com[1].txt
- http://ic###azip.com/
- DNS ASK ic###azip.com
- DNS ASK jk##j.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding